DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-102277: CVE-2026-102277: Denial of Service via Quadratic Algorithmic Complexity in brace-expansion

CVE-2026-102277: Denial of Service via Quadratic Algorithmic Complexity in brace-expansion

Vulnerability ID: CVE-2026-102277
CVSS Score: 5.3
Published: 2026-09-29

An uncontrolled resource consumption vulnerability exists in the brace-expansion JavaScript library. Due to an algorithmic flaw in parsing a legacy Bash-compatibility quirk involving {a},b}-shaped expansion structures, untrusted inputs containing many trailing closing braces trigger successive full-input rescans. This behavior yields quadratic CPU time complexity and high memory overhead, allowing remote, unauthenticated attackers to cause a Denial of Service (DoS) by blocking the single-threaded Node.js event loop.

TL;DR

The brace-expansion JavaScript library suffers from an O(N^2) quadratic complexity vulnerability when parsing legacy {a},b}-shaped structures with many trailing braces. This allows remote attackers to trigger a Denial of Service by blocking the single-threaded Node.js event loop.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-400, CWE-407
  • Attack Vector: Network (Remote)
  • CVSS v3.1 Score: 5.3
  • EPSS Score: 0.00301
  • Impact: Availability (Denial of Service)
  • Exploit Status: Proof-of-Concept
  • KEV Status: Not Listed

Affected Systems

  • Applications utilizing brace-expansion in Node.js environments for path or glob matching
  • Downstream packages like minimatch and glob utilizing vulnerable versions of brace-expansion
  • brace-expansion: < 1.1.21 (Fixed in: 1.1.21)
  • brace-expansion: >= 2.0.0, < 2.1.7 (Fixed in: 2.1.7)
  • brace-expansion: >= 3.0.0, < 3.0.9 (Fixed in: 3.0.9)
  • brace-expansion: >= 4.0.0, < 5.0.12 (Fixed in: 5.0.12)

Code Analysis

Commit: 33a5ef1

Fix: limit rewrites on v5/ESM branch

Commit: bdff773

Fix: limit rewrites on v2 branch

Commit: c55e67d

Fix: limit rewrites on v3 branch

Commit: ffdfa3e

Fix: limit rewrites on v1 branch

Mitigation Strategies

  • Upgrade the brace-expansion package to a patched release version
  • Sanitize user inputs to reject strings containing excessive consecutive brackets
  • Implement edge WAF filtering rules to drop payloads matching patterns of excessive trailing braces

Remediation Steps:

  1. Locate instances of the brace-expansion library within the software dependency tree using npm audit or yarn audit.
  2. Force update the dependency to version 1.1.21, 2.1.7, 3.0.9, or 5.0.12 depending on the major version branch in use.
  3. In corporate environments where direct dependency upgrades are delayed, apply a regular expression filter at the application gateway to reject patterns like '{[^}]+}[}]{10,}.*,'.

References


Read the full report for CVE-2026-102277 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)